GLPI 11.0.8 / 10.0.26, critical RCE via form import and complete MFA bypass in the public-sector ITSM platform
GLPI patches a critical form-import RCE and a full MFA bypass in the ITSM/asset platform widely run by EU public-sector, education and healthcare
Defender actions
- Update internet-facing GLPI instances to 11.0.8 (11.0.x) or 10.0.26 (10.0.x) now, the release fixes a critical form-import RCE and a complete MFA bypass that together defeat the authentication hardening the 11.x branch specifically introduced.
Analysis
GLPI 11.0.8 and 10.0.26 shipped on 2026-06-24, fixing 16 vulnerabilities (16 addressed in 11.0.8, 9 in 10.0.26), but the CVEs were publicly disclosed on 2026-07-21 and CERT-FR published its advisory CERTFR-2026-AVI-0909 on 2026-07-22; the in-window event that brings the flaws to defenders' attention (GLPI Project, 2026-06-24; CERT-FR, 2026-07-22). Two flaws are critical: CVE-2026-48482, remote code execution via GLPI 11's native form-import feature; an unsafe parsing/deserialization path in the import handler that gives an attacker who can submit a crafted form file code execution with application privileges; and CVE-2026-52848, a complete bypass of GLPI 11's multi-factor authentication mechanism, defeating the 2FA hardening the 11.x branch specifically introduced (GLPI Project, 2026-06-24). High-severity entries add exploitation depth: account takeover by brute-forcing the 2FA code itself (no rate-limiting on OTP verification, CVE-2026-49470), privilege escalation through the authtype API (CVE-2026-53625), SQL injection in dropdown and history-tab components (CVE-2026-47678, CVE-2026-53629), arbitrary file deletion (CVE-2026-47679) and arbitrary document read (CVE-2026-53626), plus stored and reflected XSS (IT-Connect, 2026-06-25). Affected are GLPI 11.0.x before 11.0.8 and all versions before 10.0.26; no source in this run reports in-the-wild exploitation.
Cited evidence
[SECURITY - ==CRITICAL== 11.0] RCE via Form import (CVE-2026-48482)
De multiples vulnérabilités ont été découvertes dans GLPI. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.